LEGAL

Privacy Policy

Your privacy matters to us. This policy explains what we collect, why, and how we protect it.

Effective Date: March 22, 2026 · Last Reviewed: August 29, 2026

Effective Date: March 22, 2026 · Last Reviewed: August 29, 2026

Your privacy matters to us. This Privacy Policy explains how Crfted, Inc. ("Crfted," "we," "our," or "us"), a Delaware public benefit corporation, collects, uses, shares, and protects information about you when you use the Crfted platform, website at crfted.co, and related services (collectively, the "Platform"). We have written this Policy to be clear and readable. If you have questions after reading it, please write to us at hello@crfted.co.

By creating an account or using the Platform, you agree to the collection and use of information in accordance with this Privacy Policy. This Privacy Policy is incorporated into and forms part of our Terms of Service.

1. Information We Collect

We collect information in the following ways:

1.1 Information You Provide Directly

When you create an account, make a purchase, open a Maker shop, or contact us, you may provide:

  • Account information: name, email address, and password;
  • Profile information: profile photo, shop name, bio, and social handles;
  • Payment and identity information: for Buyers, payment card or bank details processed and stored by Stripe; for Sellers, bank account information, Social Security Number or Employer Identification Number (via W-9), and government-issued ID required by Stripe for KYC verification;
  • Transactional information: shipping addresses, order details, custom order specifications, and communications related to orders;
  • Content you post: listing photos and videos, descriptions, Maker Journal posts, reviews, messages, and other user-generated content; and
  • Communications with us: emails, support tickets, and any other correspondence you send to Crfted.

1.2 Information Collected Automatically

When you use the Platform, we automatically collect certain technical information, including:

  • Log data: IP address, browser type and version, device type, operating system, referring URLs, pages visited, and time and date of your visit;
  • Usage data: features you use, searches you conduct, items you view or save, and actions taken on the Platform; and
  • Cookies and similar technologies: see Section 6 for our Cookie Policy.

1.3 Location Data

If you grant location permission, we use your coordinates solely to sort nearby workshops and do not store your location.

1.4 Information from Third Parties

We may receive information about you from third parties, including:

  • Stripe: transaction data, KYC verification status, and fraud signals provided by Stripe in connection with payment processing;
  • Social platforms: if you connect a social media account to your Crfted profile, we may receive basic profile information in accordance with the permissions you grant; and
  • Community reports: information submitted by other users who report potentially policy-violating content or conduct.

2. How We Use Your Information

2.1 Operate the Platform

  • Create and maintain your account;
  • Process transactions and fulfill orders;
  • Release payments to Sellers;
  • Provide and improve customer support;
  • Administer disputes and enforce our policies; and
  • Send transactional communications (order confirmations, shipping updates, payout notices, and system notifications).

2.2 Maintain Safety and Integrity

  • Detect and prevent fraud, abuse, and policy violations;
  • Verify Seller and Buyer identities in accordance with KYC and legal requirements;
  • Monitor for prohibited items and content; and
  • Comply with legal obligations, including tax reporting and law enforcement requests.

2.3 Improve the Platform

  • Analyze usage patterns and performance data to improve features and user experience;
  • Conduct internal research and analytics; and
  • Debug and test new features.

2.4 Communicate with You

  • Send you Platform updates, policy changes, and important service notifications;
  • Respond to your inquiries and support requests; and
  • With your consent, send you newsletters, promotional content, and updates about Crfted’s community and featured Makers. You may opt out of marketing communications at any time by clicking “Unsubscribe” in any email or by contacting hello@crfted.co.

2.5 Legal Basis for Processing (GDPR Users)

For users in the European Economic Area or United Kingdom (applicable to future international expansion), we process your personal data under the following legal bases:

  • Contract performance: processing necessary to fulfill our agreement with you (account creation, order processing, payouts);
  • Legal obligation: processing required to comply with applicable laws (tax reporting, fraud prevention, KYC);
  • Legitimate interests: processing to operate, secure, and improve the Platform; and
  • Consent: processing based on your explicit consent (marketing communications), which you may withdraw at any time.

3. How We Share Your Information

We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes. We share information only as described below.

3.1 Between Buyers and Sellers

When a Buyer places an order, their name, shipping address, and order details are shared with the Seller to enable order fulfillment. Sellers’ shop names, profile information, and listing content are publicly visible on the Platform. Sellers are independent data controllers with respect to Buyer information they receive and are independently responsible for compliance with applicable privacy law.

3.2 Service Providers

We share information with trusted third-party service providers who assist us in operating the Platform. These providers are contractually bound to use your information only for the purposes we specify and to maintain appropriate security standards. Current material service providers include:

  • Stripe, Inc.: payment processing, KYC verification, and payout disbursement;
  • Resend: transactional and notification email delivery;
  • Cloud hosting infrastructure provider: platform hosting, deployment, and data storage; and
  • Analytics providers: aggregated, de-identified usage analytics.

3.3 Legal Compliance and Safety

We may disclose your information to government authorities, law enforcement agencies, or other third parties when we believe in good faith that disclosure is required to: (a) comply with a legal obligation or valid legal process; (b) protect the rights, property, or safety of Crfted, our users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.

3.4 Business Transfers

In the event of a merger, acquisition, restructuring, bankruptcy, or sale of all or substantially all of Crfted’s assets, your personal information may be transferred to the acquiring entity. We will provide notice of any such transfer in accordance with applicable law.

3.5 With Your Consent

We may share your information for any other purpose with your explicit, informed consent, which you may withdraw at any time.

4. Your Privacy Rights

Depending on where you live, you may have certain rights with respect to your personal information. We honor these rights regardless of whether they are strictly required by applicable law in your jurisdiction.

4.1 Rights Available to All Users

  • Access: you may request a copy of the personal information we hold about you;
  • Correction: you may request that we correct inaccurate or incomplete personal information;
  • Deletion: you may request that we delete your personal information, subject to certain legal exceptions;
  • Opt-out of marketing: you may opt out of receiving marketing communications at any time; and
  • Portability: you may request your personal data in a structured, machine-readable format.

4.2 California Residents — CCPA/CPRA Rights

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):

  • Right to know: the categories and specific pieces of personal information collected about you, the categories of sources from which it was collected, the business or commercial purposes for collection, and the categories of third parties with whom it is shared;
  • Right to delete: to request deletion of your personal information, subject to legal exceptions;
  • Right to correct: to request correction of inaccurate personal information;
  • Right to opt out of sale or sharing: Crfted does not sell personal information and does not share personal information with third parties for cross-context behavioral advertising;
  • Right to limit use of sensitive personal information: we use sensitive personal information only as necessary to provide the Platform; and
  • Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights.

California residents may exercise these rights by contacting us at hello@crfted.co with the subject line “California Privacy Request.” We will respond within 45 days of receiving a verifiable request.

4.3 EEA/UK Users — GDPR Rights

If you are located in the European Economic Area or United Kingdom (applicable to future international expansion), you have rights under the GDPR including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object to processing. You also have the right to lodge a complaint with your local supervisory authority. Contact us at hello@crfted.co to exercise these rights.

4.4 How to Submit a Request

To exercise any of your privacy rights, email hello@crfted.co with the subject line “Privacy Rights Request.” Include your name, email address associated with your account, and a description of your request. We may need to verify your identity before processing your request.

5. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy. Specific retention periods include:

  • Account data: retained for the duration of your account and for up to three (3) years following account closure, unless a longer period is required by law;
  • Transaction records: retained for a minimum of seven (7) years to comply with federal and state tax law;
  • W-9 and KYC data: retained as required by IRS regulations and applicable anti-money-laundering law;
  • Support and dispute records: retained for three (3) years following resolution; and
  • Marketing preferences: retained until you opt out, at which point we will update our records promptly.

6. Cookies and Tracking Technologies

6.1 What We Use

We use cookies and similar tracking technologies (“Cookies”) to operate and improve the Platform. For full details, see our Cookie Policy. In brief, we use:

  • Essential/Strictly necessary cookies: required for the Platform to function (session management, authentication, shopping cart). These cannot be disabled without impacting core functionality;
  • Analytics cookies: help us understand how users interact with the Platform. Data is aggregated and de-identified where possible; and
  • Preference cookies: remember your settings and preferences.

6.2 We Do Not Use Advertising Cookies

Crfted does not use third-party advertising cookies, behavioral tracking pixels, or retargeting technologies. We do not place retargeting cookies or work with advertising networks. If you use our cookie consent tool to enable “Personalization,” the cookies used are operated by Crfted directly to improve your on-Platform discovery experience — they are not shared with or operated by third-party advertising networks.

6.3 Managing Cookies

You can control Cookie settings through your browser settings. Note that disabling essential Cookies may affect your ability to use certain Platform features, including checkout. See our Cookie Policy for full details.

7. Data Security

We implement commercially reasonable technical, administrative, and physical security measures to protect your personal information. These measures include:

  • Encrypted data transmission (HTTPS/TLS) for all Platform communications;
  • Encrypted storage of sensitive data including passwords and financial information;
  • Access controls limiting internal access to personal information on a need-to-know basis;
  • Regular security monitoring and updates to our infrastructure; and
  • Payment card data is handled entirely by Stripe, which maintains PCI DSS compliance; Crfted does not store full payment card numbers.

No method of electronic transmission or storage is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you and applicable authorities as required by law.

8. Children's Privacy

The Platform is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided personal information to us, we will delete that information promptly. If you believe a child under 13 has created an account or provided information to us, please contact us immediately at hello@crfted.co.

9. Third-Party Platforms and Links

The Platform may link to or integrate with third-party websites, services, or social media platforms. Crfted does not control and is not responsible for the privacy practices of any third party. This Privacy Policy applies only to the Crfted Platform.

10. Sellers and Buyer Data

Sellers who receive Buyer personal information through the Platform may use such information only to fulfill the order and for directly related customer service communications. Sellers may not: (a) use Buyer information for unsolicited marketing; (b) sell or share Buyer information with any third party; (c) contact Buyers outside the Platform using information obtained through Platform transactions; or (d) use Buyer information for any purpose inconsistent with the order for which it was provided.

By selling on Crfted, Sellers agree to maintain appropriate security measures for any Buyer information they handle and to comply with all applicable privacy laws in their jurisdiction, including the CCPA, GDPR, and any other applicable state or national privacy legislation.

11. International Users

The Platform is currently available in the United States only. All Platform data is stored and processed in the United States. If you access the Platform from outside the United States, you do so at your own initiative and are responsible for compliance with local laws.

When Crfted expands to additional markets, this section will be updated to address applicable data transfer mechanisms, including Standard Contractual Clauses or other GDPR-compliant transfer frameworks as required.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by: (a) sending an email to the address associated with your account; (b) posting a notice on the Platform; and (c) updating the “Effective Date” at the top of this Policy. We will provide at least thirty (30) days’ notice before material changes take effect.

13. Contact Us — Privacy Questions

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, or to exercise any of your privacy rights, please contact us:

Crfted, Inc. — Privacy Inquiries
Email: hello@crfted.co (subject: “Privacy Request”)
Website: crfted.co/privacy
Support: crfted.co/support
Mailing Address: 3556 S 5600 W #1-722, Salt Lake City, UT 84120, United States

We are committed to addressing all privacy questions and concerns promptly and transparently. If you are a California resident and believe we have not adequately responded to your privacy request, you may contact the California Attorney General’s office.